First published: Fri Sep 11 2009(Updated: )
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo | <=4.6.3 | |
Mambo | =4.6.2 | |
brilaps mostlyce | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7213 is classified as a medium severity vulnerability due to its potential for exploiting cross-site scripting (XSS).
To fix CVE-2008-7213, upgrade to MOStlyCE version 2.4 or later, or ensure that Mambo is updated to a version higher than 4.6.3.
CVE-2008-7213 affects users of Mambo version 4.6.3 and earlier, as well as MOStlyCE versions up to and including 2.0.
CVE-2008-7213 allows attackers to execute arbitrary web scripts or HTML, leading to possible data theft, session hijacking, or site defacement.
CVE-2008-7213 was publicly disclosed in February 2008.